Search NASA⌕ Search

SEARCH · Search NASA

Results for “CyTRICS”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

CyTRICS Impact-Based Prioritization Process

Cyber Testing for Resilient Industrial Control Systems™ (CyTRICS™) is the Department of Energy’s (DOE’s) program for cybersecurity vulnerability testing, digital subcomponent enumeration, and forensic assessment. CyTRICS leverages best-in-class test facilities and analytic capabilities at six DOE National Laboratories and strategic partnerships with key stakeholders including technology developers, manufacturers, asset owners and operators, and interagency partners. During the program’s development, CyTRICS established a unique methodology for prioritizing digital components within operational technology (OT) and industrial control systems (ICS) in the Energy Sector Industrial Base (ESIB) for cyber vulnerability testing. The CyTRICS prioritization process leverages multiple characteristics of systems, components, and their contextual deployment to calculate a quantification of individual digital components for CyTRICS testing. The initial version of the CyTRICS prioritization process was premised largely upon the impact which could result to an energy sector industrial control system if the digital component under testing was compromised, either through malicious means, faulty engineering, or other modes. CyTRICS has termed this process the “CyTRICS Impact-based Prioritization Process.” This paper describes the factors identified for use in the Impact-based Prioritization process and identifies the rationale for inclusion. During development, three National Laboratories piloted this prioritization process and generated prioritization scores for seven systems. Following the piloting of the process, laboratory subject matter experts (SME) validated that the numerical scores generated by the prioritization process were consistent with their knowledge of the impact that may occur should any of these systems be disrupted. The following document explains how to perform the prioritization process to generate prioritization scores for energy sector systems. After outlining assumptions required to conduct the process, it describes how to identify and elicit data which can be leveraged to evaluate a system and assign numerical values for each factor. The prioritization process uses different weights on different factors; rationale for each weight is included within the paper. Additionally, the paper includes some recommendations for future enhancements to prioritization, including lessons learned from developing and piloting the process. Finally, a comprehensive appendix includes example documents to be leveraged by those looking to execute the prioritization process.

99 GENERAL AND MISCELLANEOUS↗

Cytrics Repository Of Analysis Tools And Engineering Resources

Cybersecurity Testing for Resilient Industrial Control Systems (CyTRICS) is a DOE-funded project that works with vendors to evaluate the cybersecurity of equipment used in US critical infrastructure. In the process of testing systems, CyTRICS researchers often develop custom tools. The tools in this repository were developed during multiple CyTRICS tests to assist with the testing process. They help solve problems encountered by CyTRICS researchers and address uncommon testing subjects for which limited tooling is available. They are useful to other researchers working on similar systems and architectures.

Laird, SutterE↗

CyTRICS™ Assessment Report: Whole Home Battery Applications

This report examines the software supply chain security posture of mobile applications developed for consumer whole-house battery and energy-management products. While these applications are not currently integrated with critical infrastructure, their growing role in connected energy domain spaces underscores the importance of understanding the external dependencies, permission structures, and runtime behaviors that could introduce systemic risk; particularly, if adoption expands into more critical environments.

25 ENERGY STORAGE↗

SLIA Reference Architecture Models

The SLIA Reference Architecture Models project, sponsored by the DOE CESER Energy CyberSense Program (Oct 2024–Sep 2025), advanced LLNL’s PySCES simulation tool to better support CyTRICS Prioritization and Initial Risk Assessment (PIRA) reference architectures. Key achievements include enhancements to the PySCES transmission substation facility model, expanded asset coverage, and enhancements to the PySCES code base. Software improvements reduced code complexity, migrated PySCES to Python version 3.11, introduced an object-oriented design, and added a schema database for easier updates and validation. New features support device criticality assessments and a more precise parametric simulation mode. Remaining gaps include model validation, workflow limitations, Monte Carlo convergence issues, full device criticality metric implementation, model fidelity, and general software improvements. Continued development is recommended to address these gaps and fully align PySCES with CyTRICS PIRA requirements.

97 MATHEMATICS AND COMPUTING↗

Idaho National Laboratory Energy Cybersecurity Programs Update

This brief presentation provides a status update on three Idaho National Laboratory energy cybersecurity programs of particular interest to NERC Reliability and Security Technical Committee annual in-person Security Groups summit. Public information on the following three programs is included: Cybersecurity for Operational Technology Environments (CyOTE™) program Cyber-Informed Engineering (CIE) Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, and associated high-level information on the Energy Software Bill of Materials POC, Executive Order 14017, and the Energy Cyber Sense Act

24 POWER TRANSMISSION AND DISTRIBUTION↗

Assessing Energy Infrastructure Devices for Vulnerabilities

Industrial control systems prove to be vital to the health and security of the nation in our critical infrastructure. Critical infrastructure includes the most foundational systems to support modern civilization which includes water and wastewater systems, communications, and the electricity we use to name a few sectors. However, these devices' overall composition remains largely unknown and are untested from a cyber security perspective. As part of the Cyber Testing for Resilient Industrial Control Systems (CyTRICS) program, I analyzed one such energy infrastructure device to better understand how it functions, what hardware and software components are present within it, and assess it for security vulnerabilities. To achieve this, I reverse engineered binary files using Ghidra to understand system functionality and learned more about how to collaborate with other researchers on a shared Ghidra project. I learned more about how web sockets function and how to interact with them through Python to test if they are secure or not. This work led me to assess possible vulnerabilities in this device and provide a better understanding of its composition and function, which are essential to INL's mission of securing our nation's energy infrastructure.

99 - GENERAL AND MISCELLANEOUS↗